The Longitude Problem: Why Ground Truth Beats Guesswork in the AI Age

For centuries, sailors died because they could estimate their position but not confirm it. Attackers targeting your company today face the same gap, and your best defence is the same one that finally solved navigation.

ThreatVectr Newsdesk· 4 min read
A modern high-end smartphone lying face-up on a dark matte desk, its screen glowing with a soft geometric privacy pattern that makes the display appear dark fro
Share

Key points

  • Criminals targeting businesses today largely work from guesswork, piecing together who approves payments and which email domains are real from publicly available clues.
  • AI-generated phishing emails, which are fake messages crafted by artificial intelligence to look convincing, can now pass every spelling and tone check defenders once relied on.
  • Defenders hold an asymmetric advantage: they can access ground truth, meaning confirmed internal facts, that attackers must guess at from the outside.
  • Maintaining that ground truth, keeping records of who actually approves payments and which domains your company owns, is the practical work that turns the advantage into protection.
  • A single confirmed fact can kill a sophisticated fraud attempt that defeated every other filter.

What does an eighteenth-century navigation crisis have to do with your inbox?

Ships once knew how far north or south they were. Where they were east to west was a guess, and wrong guesses meant shipwrecks. After a British fleet wrecked on its own coastline in 1707, Parliament offered a prize of up to 20,000 pounds for a solution.

The eventual answer came not from a smarter calculation but from a better fact. A carpenter named John Harrison built a clock precise enough to hold Greenwich time across months at sea. Compare that time to local noon, do the arithmetic, and your position stops being a probability. It becomes a statement.

CSO Online drew that parallel to modern security, and it holds exactly.

How do attackers actually target a company today?

They guess. Criminals scrape job listings, LinkedIn profiles, and company websites to build a picture of who approves wire transfers, which domains belong to the organisation, and what normal internal messages look like. That picture is assembled from the outside, often out of date, and never fully confirmed.

AI makes the guesses more convincing. A model can now write a message from a fake CFO with perfect grammar, correct tone, and a plausible email thread. Every spelling-and-tone filter passes it. Every reputation check clears it, because nothing looks unusual on the surface.

What kills it is a fact.

What does 'ground truth' mean in practice?

Ground truth, in this context, means a confirmed internal record: the actual list of who is authorised to approve a payment on a given account, the exact set of email domains your company owns, the vendors that genuinely exist in your supplier list.

A system holding those facts does not need to decide whether a message looks suspicious. It checks whether the message contradicts something already known to be true. If the person named as approver is not the approver of record, and the reply address is not one of your registered domains, the fraud dies on a fact rather than a hunch.

That advantage is real but not permanent.

Should organisations be worried about keeping those records current?

Yes. Ground truth decays. Approvers change jobs. Domains accumulate as business units grow. Vendors get added without being logged centrally. A fact that nobody maintains quietly becomes an out-of-date guess wearing a confident face.

Keeping those records accurate is the hard, unglamorous work. It is the equivalent of winding every chronometer on every ship, not just the flagship.

For anyone deciding where to start: identify who in your organisation can actually authorise a payment. Confirm it. Write it down. Confirm it again next quarter. Attackers are computing a plausible version of that answer from the outside. The question is whether your defences are still doing the same thing beside them, or carrying the fact instead.

Common questions

Would better email filters stop these attacks?

Not reliably. AI-written messages can pass grammar, spelling, and tone filters because they are well-written. Detection based on ground truth, checking confirmed internal facts rather than patterns, is what stops messages that look legitimate but contradict what you know.

Does multi-factor authentication, the extra login step beyond a password, help here?

For account takeover, yes, it is essential. For social engineering fraud where a criminal impersonates a known colleague by email rather than logging in, multi-factor authentication does not help directly. Verified internal records of who can authorise what are the relevant control.

© 2026 Threat Vectr